news.mlab.sh
Back to the feed
vulnerability

Cisco Zero-Day Highlights API Endpoint Authentication Issues

CriticalCVSS 10.0
Summary

Cisco has disclosed a critical zero-day vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) that allows attackers to bypass authentication and gain unauthorized access to devices. This flaw, under active exploitation, stems from insufficient authentication controls within an ISE API endpoint. Due to ISE's role in managing network access for numerous other Cisco APIs, a successful exploit could lead to widespread compromise and impersonation of other hosts, highlighting a broader industry trend of API authentication weaknesses.

Cisco has announced a critical zero-day vulnerability (CVE-2026-76460) impacting its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The flaw, receiving a maximum CVSS score of 10/10, is an authentication bypass vulnerability within an ISE API endpoint. According to Cisco, the issue arises from "insufficient authentication control" on this API endpoint, allowing attackers to send crafted requests and gain unauthorized access to vulnerable devices without requiring any user interaction.

"An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint," Cisco stated in its advisory. "A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface." The vulnerability was disclosed and patched on Wednesday, and the Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on the same day.

Cisco also disclosed and patched several other bugs impacting ISE and ISE-PIC with similar API authentication issues. The first, CVE-2026-20223, is an insufficient authentication flaw in the internal REST APIs of Cisco Secure Workload, with a maximum CVSS score of 10/10, disclosed in May. The second, CVE-2026-20129, is a critical API authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager with a 9.8 CVSS score, disclosed in February.

Threat intelligence provider BitSight noted that ISE is at the heart of many organizations’ identity and network access infrastructure, determining which users and devices can connect to a network and what they can access after connecting. Successful exploitation of CVE-2026-76460 could give threat actors root-level access to that infrastructure, creating visibility, integrity, and availability risks across a much wider environment.

To mitigate the vulnerability, Cisco recommends using infrastructure access control lists (iACLs) to restrict management and control plane traffic, but emphasizes that this is a temporary solution and urges customers to upgrade to a fixed version of ISE or ISE-PIC. The company also advises administrators to cross-check network and firewall logs for suspicious activity, including unexpected uploads from the affected device to external IP addresses or downloads from malicious IP addresses, as exploitation could allow threat actors to delete or conceal evidence of exploitation and indicators of compromise (IoCs).

Read the full article at Dark Reading